Privacy

Privacy Policy

Effective 14 September 2026Version 2.0

This Policy explains what we collect, why, how long we keep it, and who we give it to. The short version: we log calls in detail, we keep those logs, and we hand them over when the law requires it.

01Introduction

This Privacy Policy explains how Machport LLC (“Spoofey”, “we”, “us”), a New Mexico limited liability company with its principal address at 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA, collects, uses, shares and retains personal data when you use our website and calling service (the “Service”).

We are the data controller. As a US company we do not operate under one single omnibus privacy statute; our obligations come from applicable US federal law and the state law of wherever you live (including the CCPA/CPRA for California residents — see section 7), and our contact point for privacy matters is privacy@spoofey.com.

Where you are matters more than where we are. Data-protection law generally follows the individual, so if you are in the EEA, the UK, California or another jurisdiction with extraterritorial reach, that law applies to our processing of your data even though we are established in the United States. Where it does, we comply with it and you have the rights set out in section 7. We have not appointed an EU/UK Article 27 representative. If our EEA or UK user base becomes significant, this is a real open item, not an oversight to gloss over.

The short version. Every call is logged in detail (your own number, the caller ID you presented, the number you dialled, and the IP address you connected from), and those records identify you. We keep them, and we disclose them to law enforcement, regulators and carriers where we are required to or where we believe in good faith that a crime is being committed. We would rather you knew that up front than found out later.

02What we collect

Information you give us

DataWhere it comes from
Username, email address, hashed passwordSign-up
Country, timezone, profile visibility settingAccount settings
Registered Number: your own telephone number, which we call to connect youRequired before you can place calls; verified by an automated call or message to that number
Identity documents, proof of address, source of funds, or authorisation from a number's subscriberNot collected for ordinary accounts. Requested only on escalation: risk flags, high spend, disputes, complaints or legal enquiries (see Terms, section 3)
Forum posts, direct messages, profile contentCommunity features
Correspondence with support and abuse reports you makeEmail and in-product

Call records

Spoofey is a callback bridge: we ring your own number first, then dial the destination and connect the two. That means every call produces records for two legs.

LegWhat we record
First leg: to youYour Registered Number, the time we dialled it, whether and when you answered, and the duration
Second leg: to the destinationThe destination number, the caller ID presented, timestamps, duration, disposition, and any failure or block reason
BothRoute and carrier used, credits consumed, and the account and IP address that requested the call

These are call detail records and they are the core of what we hold about you. Note the consequence of the architecture: a verified telephone number that reaches you personally is attached to every call you make.

We do record call audio. We may record and monitor either leg of a call placed through the Service, including any audio carried on it, for the reasons and on the consent basis set out in full in the Terms of Service (section 12), which forms part of this Policy by reference. Recordings are retained for the period set out in the table below, and are accessible only to personnel who need them to operate the Service, investigate abuse, resolve billing disputes, or respond to a valid legal or carrier request.

Information collected automatically

Payment information

Payments are processed by third-party providers. We receive the amount, currency, status, timestamp and a transaction or invoice reference. For cryptocurrency payments we also receive the asset and the on-chain transaction identifier, which may be linkable to your wallet and its history by anyone. We do not receive or store full card numbers.

Information from others

We receive reports and signals from called parties, number subscribers, carriers, industry traceback consortia, regulators, law-enforcement bodies, fraud-prevention and sanctions-screening services, and identity-verification providers.

03Why we use it, and our legal basis

Where the UK GDPR, EU GDPR or a similar regime applies, we rely on the following bases.

PurposeLegal basis
Creating and running your account; placing your calls; taking payment; providing supportPerformance of a contract
Operating the anti-fraud and risk system; enforcing the high-risk number blacklist; detecting and preventing fraud, abuse, harassment and misuse of the ServiceLegitimate interests: protecting the public, our carriers and our business from serious harm and legal risk
Identity and entitlement verification; sanctions and restricted-party screeningLegal obligation, and legitimate interests
Retaining call detail records; responding to traceback requests, regulators, courts and law enforcementLegal obligation, and legitimate interests
Security, logging, monitoring, backup and incident responseLegitimate interests, and legal obligation
Service and reliability improvement, aggregate analyticsLegitimate interests
Marketing email, where applicableConsent: withdrawable at any time
Establishing, exercising or defending legal claimsLegitimate interests, and legal claims

Where we rely on legitimate interests we have considered the impact on you. Given the potential for this category of service to be misused to defraud or harass people, we consider comprehensive logging and active risk screening to be necessary and proportionate.

04Automated decision-making

Our anti-fraud risk system automatically evaluates accounts, payments and individual calls, and can automatically decline a call, apply limits, hold a payment, or suspend an account. This can produce legal or similarly significant effects for you.

We carry out this processing because it is necessary for the performance of our contract with you and for compliance with our legal obligations, and because without it the Service could not be operated responsibly. Where you are subject to a significant automated decision and the law gives you the right, you may contact privacy@spoofey.com to request human review, to express your point of view and to contest the decision.

We cannot disclose the specific signals, weights or thresholds, because publishing them would let the system be circumvented by the people it exists to stop.

05Who we share it with

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

06How long we keep it

CategoryRetention
Account recordsFor the life of the account, then 12 months after closure
Call detail records24 months from the call: long enough to answer traceback and law-enforcement requests, which frequently arrive months after the event
Registered Number and its verification recordWith the account record, then retained with the call records it is attached to
Identity documents, where escalation required them5 years after account closure, or as required by anti-money-laundering law
Payment and transaction records7 years, for tax and accounting purposes
Risk, abuse and enforcement records, including records of terminated accountsRetained on a long-term basis so that banned users can be prevented from returning
Messages and forum contentUntil deleted by you or by us, plus backup cycle
Server and security logs90 days

We may keep data for longer where it is subject to a legal hold, an ongoing investigation, or an actual or anticipated legal claim.

07Your rights

Depending on where you live, you may have the right to access your data; to correct it; to delete it; to restrict or object to processing; to data portability; to withdraw consent; and to complain to a supervisory authority.

To exercise any right, email privacy@spoofey.com from your account address. We may need to verify your identity. We will respond within the period the applicable law requires.

One limit on deletion, so it is not a surprise. We cannot delete call detail records, risk records or verification documents while we are required to keep them, while they are needed to establish or defend a legal claim, or where deletion would stop us meeting obligations to law enforcement and carriers. Outside those cases we will action a deletion request normally.

08International transfers

We operate internationally. Our infrastructure is located in the United States and Canada, and your data may be processed there and in any country where a carrier in the call path operates. Calls are by their nature routed across borders, and the destination number and the caller ID you present are necessarily disclosed to carriers in those countries.

The United States is not the subject of a blanket UK or EU adequacy decision (we have not self-certified under the EU-US Data Privacy Framework). Canada, where part of our infrastructure sits, has a standing EU adequacy decision for commercial organisations, but we do not rely on that alone. Where we receive personal data from the UK or EEA we rely on Standard Contractual Clauses or the UK International Data Transfer Addendum, together with a transfer risk assessment and appropriate supplementary measures. You may request a copy of the safeguards from privacy@spoofey.com.

09Cookies

We use a small number of cookies:

We do not currently use any third-party analytics, advertising or tracking tag on the Service. If that changes, we will list the tool here and, where the EEA/UK requires it, ask for your consent before it is set.

You can clear or block cookies in your browser, but you will not be able to sign in.

10Security

We use encryption in transit, hashed and salted password storage, access controls and least-privilege administration, audit logging, and segregation of verification documents from general account data. We also run automated rate limiting, IP and account ban controls, and an advisory fraud-risk system across the Service to reduce the impact of a compromised account or credential-stuffing attempt.

No system is perfectly secure and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, within the timeframes the law sets.

11Children

The Service is not directed to anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@spoofey.com and we will delete it and close the account.

12Changes and contact

We may update this Policy. The effective date at the top of the page shows when it last changed, and we will notify you of material changes by email or in-product notice where reasonably practicable.

Privacy enquiries and rights requests: privacy@spoofey.com
Abuse reports and unauthorised presentation of your number: abuse@spoofey.com
Law-enforcement and legal requests: legal@spoofey.com

Questions about this document? Write to legal@spoofey.com. See also the Terms of Service.